Vulnerability GHSA-g5vr-6pgg-74qv

Low Risk
LOW RISK
CVSS Score: 3.8
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
2 months ago
June 22, 2026 at 03:30 PM UTC
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible

Summary

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Details

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667

Timeline

Published
2 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
1 day ago
September 15, 2026 at 08:00 PM UTC